Impact
Vulnerability is a CWE‑284 Improper Access Control flaw in the Installation component of Oracle Siebel CRM Deployment. It allows an authenticated low‑privileged user who has logged onto the hosting infrastructure to take over the deployment. Successful exploitation results in complete loss of confidentiality, integrity, and availability of the Siebel CRM deployment application.
Affected Systems
Oracle Siebel CRM Deployment product, versions 17.0 through 26.7, is affected. All builds within this range contain the flaw in the Installation component.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 classifies it as high severity. EPSS is less than 1%, indicating a very low probability of exploitation in the current threat landscape. The vulnerability is not listed in CISA KEV. The exploit requires low‑privilege local access to the server where Siebel CRM Deployment is installed; no external network vector is documented, so the attack is considered local.
OpenCVE Enrichment